Author Topic: Cyberheists ‘A Helluva Wake-up Call’ to Small Biz  (Read 218 times)

Offline menotu

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 15282
  • ┌∩┐(◕_◕)┌∩┐
Cyberheists ‘A Helluva Wake-up Call’ to Small Biz
« on: November 06, 2012, 05:02:16 AM »
Brian Krebs  6- November 2012 (krebsonsecurity)

The $180,000 robbery took the building security and maintenance system installer Primary Systems Inc. by complete surprise. More than two-dozen people helped to steal funds from the company’s coffers in an overnight heist on May 2012, but none of the perpetrators were ever caught on video. Rather, a single virus-laden email that an employee clicked on let the attackers open a digital backdoor, exposing security weaknesses that unfortunately persist between many banks and their corporate customers

The St. Louis, Missouri-based firm first learned that things weren’t quite right on Wednesday, May 30, 2012, when the company’s payroll manager logged into her account at the local bank and discovered that an oversized payroll batch for approximately $180,000 had been sent through late Tuesday evening.

The money had been pushed out of Primary Systems’ bank accounts in amounts between $5,000 and $9,000 to 26 individuals throughout the United States who had no prior interaction with the firm, and who had been added to the firm’s payroll that very same day. The 26 were “money mules,” willing or unwitting participants who are hired through work-at-home job schemes to help cyber thieves move money abroad. Most of the mules hired in this attack were instructed to send the company’s funds to recipients in Ukraine.

The company’s financial institution, St. Louis-based Enterprise Bank & Trust, declined to comment. But of course, mistakes were made all around. Primary Systems’ employees failed to be wary of virus-laden email attachments, and relied too heavily on its firewalls and antivirus software to block attacks. The bank failed to bat an eyelash before processing a $180,000 transfer marked as “payroll” on a Tuesday, even though the company has always processed its payroll batch on Friday mornings. It also failed to flag as strange the overnight addition to Primary’s payroll of 26 new employees located in nearly as many states, even though almost all of the victim firm’s legitimate employees are based in Missouri.The only parties to this crime who didn’t make missteps were the thieves.

Faber said he wishes the bank had explained the sophistication of the threat facing small businesses, and the exposure that these organizations face when banking online. Under “Regulation E” of the Electronic Funds Transfer Act (EFTA) consumers are not liable for financial losses due to fraud — including account takeovers due to lost or stolen usernames and passwords — if they promptly report the unauthorized activity. However, entities that experience similar fraud with a commercial or business banking account do not enjoy the same protections and often are forced to absorb the losses.

If you run a small business and bank online, ask your financial institution what services and add-ons they may offer to help you manage the risk to your accounts. If you’d like to significantly decrease the likelihood that your business will suffer a cyber heist, consider adopting a dedicated PC approach, and/or banking online only from a Live CD distribution.

Full article

Banking on a Live CD

« Last Edit: November 06, 2012, 05:04:45 AM by menotu »
PCLinuxOS 32bit KDE 4.10.1; kernel-3.4.11-pclos1.bfs & 64bit 3.2.18bfs; NVidia GeForce 8400GS 1GB 310.19 driver

Sony Vaio SVE1513A4ESI Laptop, Intel Core i5, 2.6GHz, 6GB RAM, 750GB, 15.6" Intel HD Graphics 4000

Offline Just17

  • PCLinuxOS Tester
  • Super Villain
  • *******
  • Posts: 10620
  • MLUs Forever!
Re: Cyberheists ‘A Helluva Wake-up Call’ to Small Biz
« Reply #1 on: November 06, 2012, 06:22:25 AM »
Regarding 'Banking on a liveCD'  .....  I would suggest a remaster of a PCLOS Mini ISO, with all features enabled to make it as secure as possible and allow connection ONLY to the required banking sites  etc etc.

It could be booted from CD or USB.

At least it would be a personalised secure system and not something 'off the shelf'.

MLUs rule the roost!

Linux XPS 3.2.18-pclos2.pae.bfs  32 bit
Intel Core2 Quad CPU Q9450 @ 2.66GHz
4 GB RAM
MCP51 High Def Audio
GeForce GTX 550 Ti
PHILIPS  ‎DVD+-RW DVD8701
‎Logitech ‎BT Mini-Receiver
Afatech DTT